skills/aeondave/malskill/masscan/Gen Agent Trust Hub

masscan

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides numerous examples and a shell script for running network utility commands including masscan and nmap. These commands facilitate scanning IP ranges and services. The skill also makes use of standard text-processing utilities like grep, awk, and jq to parse scan results.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines workflows that involve the agent reading and processing data generated by masscan (e.g., service banners retrieved via the --banners flag and port scan outputs). If a scanned target serves malicious strings in its banners, it could potentially influence the agent's behavior during data analysis.
  • Ingestion points: Data enters the context from external sources via results.json, masscan.out, and target files like hosts.txt as described in SKILL.md and references/tuning.md.
  • Boundary markers: No explicit boundary markers or instruction-ignoring delimiters are specified for the processing of these external output files.
  • Capability inventory: The skill utilizes shell execution for port scanning, service identification, and file creation/modification.
  • Sanitization: The provided documentation and scripts do not include steps to sanitize or filter service banners or other network-sourced data before they are processed by the agent or piped into other tools.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 09:56 AM
Security Audit — agent-trust-hub — masscan